<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/network-security/</link><description>Recent content in Network-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/network-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Android 17 Adds OS-Wide Encrypted Client Hello for Connection Privacy</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-android-17-adds-os-wide-ech-to-hide-website-visits-from-netw/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-android-17-adds-os-wide-ech-to-hide-website-visits-from-netw/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ECH support in Android 17 is a platform-level change worth tracking for mobile app TLS compatibility and enterprise network inspection assumptions, but requires no immediate action on running systems.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Android 17 adds ECH support for enhanced browsing privacy</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-android-17-adds-ech-support-to-make-web-browsing-harder-to-t/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-android-17-adds-ech-support-to-make-web-browsing-harder-to-t/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ECH support in Android 17 may affect how TLS inspection tools or corporate proxies handle traffic from managed Android devices; worth evaluating impact on your mobile security stack.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Cisco ASA and FTD Remote DoS Flaw Exploited in the Wild (CVE-2026-20349)</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-cisco-asa-and-ftd-flaw-exploited-in-the-wild-can-trigger-rem/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-cisco-asa-and-ftd-flaw-exploited-in-the-wild-can-trigger-rem/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA KEV listed, actively exploited in the wild, and a public PoC exists — patch Cisco ASA and FTD software immediately per Cisco&amp;rsquo;s advisory for CVE-2026-20349; perimeter firewall availability is at direct risk from unauthenticated remote attackers.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an edge security appliance warrants an assume-breach sweep — hunt for anomalous or malformed HTTP requests targeting ASA/FTD management interfaces and investigate any unexplained firewall availability incidents since this KEV listing date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A CISA KEV-confirmed flaw in widely deployed perimeter firewalls is a priority patching event — confirm your engineering team has this on the sprint and assess whether any availability SLAs tied to ASA/FTD deployments are at risk; DoS scope limits board-level urgency but warrants direct follow-up with the team.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-20349 — CISA KEV: listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Cisco Patches 12 SD-WAN and IOS XE Flaws Including Three CVSS 9.8 Bugs</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-cisco-patches-12-sd-wan-and-ios-xe-flaws-including-three-9-8/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-cisco-patches-12-sd-wan-and-ios-xe-flaws-including-three-9-8/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Three CVSS 9.8 flaws in widely deployed Cisco Catalyst SD-WAN and IOS XE warrant prioritized patching, but no KEV listing, public PoC, or active exploitation is reported. Schedule patching to the latest Cisco-recommended releases this sprint, prioritizing any internet-exposed SD-WAN or IOS XE autonomous-mode devices.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>TP-Link Patches 15 Omada ZTP Flaws Enabling RCE Chain</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-n/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-n/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you run TP-Link Omada for network management, schedule patching of the ZTP component this sprint — 15 chainable vulns with RCE potential are high severity, though no KEV listing or public PoC currently raises the urgency to emergency status.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Choquet-Integral Feature Aggregation Boosts Network Anomaly Detection</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-improving-network-anomaly-detection-via-choquet-integral-bas/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-improving-network-anomaly-detection-via-choquet-integral-bas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Academic research showing a feature-aggregation technique that improves IDS accuracy by up to 7% while cutting data volume significantly — worth tracking if evaluating or tuning ML-based network detection models, but no tooling or deployable artifact yet.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Entropy features improve network anomaly detection ML pipelines</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-on-the-impact-of-entropy-based-features/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-on-the-impact-of-entropy-based-features/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Research shows adding entropy-based features to supervised traffic classifiers reduces misclassifications in high-variability scenarios; worth evaluating if the team maintains its own ML-based detection pipeline.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>